Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects potential reflective code injection or in-memory loading (fileless) where a DLL or PE image is loaded by mshta.exe or powershell.exe, but the module load event lacks a valid file path on disk (or indicates a device path). This behavior is often associated with the execution of malicious payloads such as the Amatera loader, where payloads are executed directly in memory to evade file-based security detections.
Detects attempts to modify, disable, or exclude paths and processes from Microsoft Defender Antivirus using legitimate administrative utilities such as PowerShell, cmd, sc, and netsh. This behavior is indicative of an adversary attempting to evade security monitoring.
Detects processes that access sensitive browser credential or cookie files (e.g., Login Data, Cookies) followed by network activity within a 10-minute window, which is a common behavior pattern of information-stealing malware such as Amatera or ACR Stealer.
Detects execution of netsh.exe when launched from unexpected parent processes (tapctl.exe or openvpnserv.exe) from locations other than the standard System32 or SysWOW64 directories. This pattern is indicative of potential malicious activity or persistence via Netsh helper DLLs masquerading or executing via non-standard paths.
This rule identifies instances of OpenVPN-related executables (openvpn.exe, openvpnserv.exe, tapctl.exe) running on endpoints where the version is below the threshold considered patched (2.7.7). It uses file metadata and certificate information to verify the binary version and flag legacy, potentially vulnerable installations.
This rule detects the use of 'mshta.exe' to execute a file from a remote location by inspecting the command line for 'http' protocols and a specific suspicious domain. Adversaries often abuse mshta.exe to proxy the execution of malicious HTML Application (HTA) files or scripts to bypass security controls.
Detects suspicious execution of PowerShell or Mshta spawned from Explorer.exe. It looks for specific malicious indicators including references to known malicious domains, PowerShell encoding flags, hidden window arguments, or Mshta HTTP requests, which are common patterns for fileless malware or dropper execution.
Detects suspicious execution of PowerShell or Mshta spawned from Explorer.exe. It looks for specific malicious indicators including references to known malicious domains, PowerShell encoding flags, hidden window arguments, or Mshta HTTP requests, which are common patterns for fileless malware or dropper execution.
Detects the execution of msiexec.exe referencing a 'Temp.txt' file located within the user's AppData Local Temp directory, which matches a known suspicious file hash. This pattern often indicates an attempt to proxy the execution of malicious payloads via the Windows Installer utility.
Detects instances where OpenVPN service binaries (openvpn.exe or openvpnserv.exe) spawn command-line interpreters (cmd.exe or powershell.exe) with suspicious command-line characters or potentially unbalanced quotes. This behavior may indicate an attempt to leverage OpenVPN for code execution or persistence, often seen in environments where VPN configurations are manipulated to run arbitrary scripts.
Detects execution of netsh.exe when launched from unexpected parent processes (tapctl.exe or openvpnserv.exe) from locations other than the standard System32 or SysWOW64 directories. This pattern is indicative of potential malicious activity or persistence via Netsh helper DLLs masquerading or executing via non-standard paths.
Detects execution of AnyDesk from non-standard directories such as Temp, AppData, or User profile folders, often indicative of unauthorized or portable installation of remote access software.
This rule monitors for three distinct suspicious behaviors on Windows endpoints: the addition of executable files from temporary or user-writable directories to Windows registry run keys for persistence, the creation of repeated hidden log or data files in AppData directories, and unsigned processes accessing browser-related credential storage files.
Detects network connection attempts or established connections to a specific remote IP (103.141.13.26) on UDP port 3479. This pattern is often associated with command and control infrastructure or unauthorized data communication.
Detects anomalous access to specific memory sections associated with Desktop Window Manager (dwm.exe) followed by a crash of the same process within a 30-minute window. This behavioral pattern is often indicative of exploitation attempts targeting DWM memory management to achieve code execution or privilege escalation.
Detects the 'LegacyHive.exe' process initiating child processes running under the SYSTEM account context. This behavior is indicative of potential privilege escalation or malicious persistence mechanisms where a process spawns a child with elevated permissions.
This rule detects instances where a process loads 'offreg.dll' (Offline Registry Library) and concurrently accesses the SAM (Security Account Manager) file. This is a common technique used by attackers to offline-extract local account hashes without using standard registry tools, potentially bypassing basic monitoring of 'reg.exe'.
This rule detects potentially malicious JavaScript files associated with known malicious patterns or suspicious 'preinstall' script behavior within Node.js environments. It monitors for the execution of specific suspicious filenames or the use of common Node.js package management tools (npm, yarn, etc.) in contexts suggesting code generation or build-time abuse.
Detects specific process execution and command-line activity related to NVIDIA GeForce Experience, specifically focusing on scheduled task creation and suspicious file references that may mimic or abuse legitimate update mechanisms.
Detects anomalous child process creation (e.g., cmd.exe, powershell.exe, rundll32.exe) spawned by the VMware host process 'vmware-vmx.exe'. This behavioral pattern is a high-confidence indicator of potential guest-to-host virtual machine escape, specifically monitoring for activity associated with vulnerabilities like CVE-2026-59346.
Detects the creation or modification of specific dropper/loader files and service worker registration within WordPress directory structures (wp-content/plugins, wp-content/themes, wp-content/uploads). These files are often associated with the injection of malicious scripts (e.g., on-chain resolvers) to facilitate drive-by compromises by site visitors.
Page 416 of 1870



